Privacy Policy
Last Updated: September 29, 2026
Introduction
Lumin Faith is developed by Andrew Kittridge, the sole proprietor. This Privacy Policy explains how I collect, use, disclose, and safeguard information when you use the Lumin Faith mobile application (the "App") or visit lumin.faith (the "Website").
1. Information We Collect
We collect the following types of information to provide and improve our services:
- User-Generated Content: Chat messages, prayer entries, journal entries, Bible study notes, and images you choose to attach to an AI request
- Account and Authentication Data: Account identifiers and profile data from Sign in with Apple, Google Sign-In, email sign-in, or guest access
- Device and App Data: Device identifiers, push notification token, app version, and app interaction events
- Attribution Data: Install and campaign attribution data from AppsFlyer and Meta (Facebook SDK), including app install, app-open, and in-app purchase events, and your device's advertising identifier (IDFA) only when permission is granted through Apple's App Tracking Transparency prompt
- Website Analytics Data: Page views, referring pages or campaigns, browser and device information, and interactions such as selecting an App Store link
- Website Questions: If you use the "Ask" box on a Website page, the question you type, any follow-up in that conversation, and the page you asked from. We do not store your name or IP address with your question. To enforce the daily question limit, we keep a one-way hash of your IP address that changes every day and is deleted after three days.
- Email Signups: If you sign up for the weekly question email, your email address and the page where you signed up. You can unsubscribe from any email.
2. How We Use Your Information
We use the information we collect to:
- Provide AI-powered spiritual guidance and Bible study assistance
- Store and synchronize your journal entries, conversations, and notes across your devices
- Track your reading streaks to encourage consistent spiritual practice
- Deliver daily inspiration and verses tailored to your spiritual journey
- Authenticate your account and maintain your session
- Send push notifications for daily inspiration (with your permission)
- Measure app install attribution and campaign effectiveness
- Understand which Website pages are useful and measure whether a Website visit leads to the App Store
- Answer questions asked on the Website and learn which questions our guides should cover next
- Send the weekly question email to people who asked for it
3. Data Sharing and Third Parties
Anthropic (Claude)
Chat answers in the App and answers to questions asked on the Website are generated by Anthropic's Claude models. We share the message, limited recent conversation context, and any image you choose to attach for that request.
- Data Shared: Your chat messages or Website question, recent conversation context, and images you choose to attach for AI understanding
- Purpose: Generating AI responses for Christian conversation, Bible study, prayer, and Website questions
- Third Party Location: United States
- Privacy Policy: https://www.anthropic.com/legal/privacy
Grok API (x.ai)
Grok API, operated by x.ai, generates daily content, voice features, and some analysis, and answers chat and Website questions when Claude is unavailable. For those requests we share your messages, limited recent conversation context, and any image you choose to attach.
- Data Shared: Your chat messages, recent conversation context, and images you choose to attach for AI understanding
- Purpose: Generating AI responses for Christian conversation, Bible study, prayer, journaling, and sermon features
- Third Party Location: United States
- Privacy Policy: https://x.ai/privacy
Google Firebase
We use Firebase services (such as Authentication, Firestore, Cloud Functions, Cloud Messaging, and Analytics) to operate core app features and reliability.
AppsFlyer (Install Attribution)
We use AppsFlyer to measure app install attribution and campaign performance, including campaigns run on X Ads.
- Data Shared: Device identifiers and app interaction events related to attribution
- Purpose: Measuring ad attribution and campaign analytics
Meta (Facebook SDK — Install Attribution)
The App includes Meta's Facebook SDK so we can measure the performance of ads we run on Facebook and Instagram.
- Data Shared: App install and app-open events, in-app purchase events (such as a subscription purchase and its price), basic device information (such as device model and OS version), and your device's advertising identifier (IDFA) only if you allow tracking through Apple's App Tracking Transparency prompt
- Purpose: Measuring ad attribution and campaign performance
- Not Shared: Your conversations, prayers, journal entries, Bible notes, or anything else you write in the App
- Privacy Policy: https://www.facebook.com/privacy/policy/
Google Analytics and Google Ads (Website Measurement)
We use Google Analytics and Google Ads conversion measurement on the Website to understand page usage and whether visitors select an App Store link.
- Data Processed: Website page and interaction events, traffic source, and browser or device information
- Purpose: Website analytics, App Store conversion measurement, and campaign effectiveness
- Privacy Information: Google Privacy Policy
X Pixel (Website Campaign Measurement)
We use the X website tag to measure visits and campaign performance.
- Data Processed: Website visit and interaction data, along with browser or device information
- Purpose: Campaign measurement and attribution
- Privacy Information: X Privacy Policy
Apple Services
We also use Apple services such as APNs and SKAdNetwork to support notifications and privacy-preserving attribution.
We do not sell your personal data.
4. Data Storage and Security
Storage Locations
- Firebase services: App account and content data are stored in Firebase-managed infrastructure
- Local Device: Authentication state and preferences are stored locally on your device
- Attribution providers: Limited attribution data may be processed by AppsFlyer, Meta (Facebook SDK), and Apple SKAdNetwork
Security Measures
- All network communications use HTTPS/TLS encryption
- Access controls are used for authenticated app data
- Biometric authentication (Face ID/Touch ID) is handled by iOS; we do not store biometric data
- API keys and sensitive credentials are stored securely
5. Data Retention
We retain your data for as long as your account is active or as needed to provide you services. You can delete your data at any time through the app's account settings. When you delete your account, all associated data will be permanently deleted from our systems.
6. Your Rights and Choices
You have the following rights regarding your data:
- Access: You can access your data through the app at any time
- Deletion: You can delete your account and all associated data through the app's account settings
- Opt-Out: You can disable push notifications in your device settings
- Tracking Choice: You can allow or deny tracking through Apple's App Tracking Transparency prompt and change your preference in iOS Settings
- Meta Activity: If you use Facebook or Instagram, you can review and disconnect activity that apps share with Meta in your account's "Your activity off Meta technologies" settings
7. Children's Privacy
Our app is suitable for users of all ages. We do not knowingly collect personal information from children under 13 without parental consent. If you believe we have collected information from a child under 13, please contact us immediately.
8. Data Tracking
We use AppsFlyer and Meta's Facebook SDK for app-install and campaign attribution, and Google Analytics, Google Ads, and the X website tag for Website analytics and campaign measurement.
- If you allow tracking, your device's advertising identifier (IDFA) may be used for attribution.
- If you do not allow tracking, attribution is limited and may rely on privacy-preserving signals such as SKAdNetwork.
- Website measurement may use cookies or similar browser technologies. You can limit these through your browser or device settings.
- We do not show third-party ads inside the app.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy in the app and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
10. Contact Us
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR), including the right to access, update, or delete your personal information, the right to data portability, and the right to object to processing of your personal information.
12. California Privacy Rights
If you are a California resident, you have the right to know what personal information we collect, use, and share, and to request deletion of your personal information. We do not sell your data.